Questions tagged [watchguard]

Watchguard make firewalls and other network devices, and related management and monitoring software.

Watchguard (http://www.watchguard.com) is an American network security company, which creates firewalls, wireless access points and associated network security devices, management and monitoring software.

Their main products include:

The Watchguard XTM firewall range

These are targeted at small to medium businesses, and they focus on being feature-rich with network features (site-to-site VPNs, remote user VPNs, firewall clustering, multiple WAN connections, VLANs, QoS and bandwidth reservations, bandwidth limits and very configurable firewall policies), high level control and monitoring of network traffic and internet use (website blocking by category, specific application blocking, per-user and per-group policies) and defense-in-depth with integrated security services (AntiVirus, AntiSpam, Intrusion Prevention signatures, deep packet inspection and protocol analysis for HTTP/HTTPS/FTP/DNS/etc.).

Watchguard firewalls are available as small office devices (XTM 2 and XTM 3 series) with optional integrated WiFi, fullsize rackmount devices for central offices and datacenters (other XTM and M devices), and as virtual machines (the XTMv range) for VMware and Hyper-V deployment.

Their business model is to have a standard firewall software offering, with the more advanced features available by purchasing licensing upgrades, and to have the same management tools, configuration format and monitoring apply up and down the hardware range. The hardware range is differentiated by processing power, memory and number of interfaces of different speeds, although some of the advanced features are unavailable on the smallest models or the XTMv virtual firewalls.

Watchguard XCS Range

The XCS devices are dedicated email filtering devices, with detailed control of users and groups, attachments, content scanning and filtering.

Watchguard AP range

These are wireless access points]1 designed to be used with a Watchguard firewall. The configuration is done as part of the firewall configuration and the access points pick up their settings from the firewall.

Watchguard SSL range

Dedicated SSL VPN portal device for end user access to a central site. They offer The features in these are increasingly included in by the newer firewall firmwares,

Their software includes

Watchguard System Manager

The desktop version of the firewall management software, it comes in two parts - firebox system manager for connecting to a firewall and seeing live status, traffic log messages, running diagnostic commands, and policy manager for editing the firewall policies and general device configuration.

Their firewalls also have a web interface for policy configuration, which is increasingly where Watchguard's focus is going.

Watchguard Dimension

A virtual machine appliance which integrates logging from Watchguard firewalls, alerting from those logs, and analysing the logs and presenting a web interface of the results.

The analysis covers things like bandwidth use per policy, per host, per server, per connection type. Internet access / website use per user or group. Numbers of connections per policy. Attacks detected, and their sources. Usage levels at different times of day, and so on.

Watchguard LogServer and ReportServer

These are Windows services which accept encrypted logging connections from Watchguard firewalls and store them in a PostgreSQL database, it can send email email alerts on firewall log events.

ReportServer analyses the logs and generates reports of internet traffic use, bandwidth use, and so on.

Both of these are being replaced by Watchguard Dimension.

Watchguard Central Management Server

A Windows service which manages firewalls, giving a single place to connect to for firewall management. It can save configuration revision histories, show diffs, and allow configuration rollback, schedule configuration changes and firmware upgrades, and has some support for firewall policy templates and VPN templates.

Utility software

Single-Sign-On helper services, for installing on Windows domain controllers, desktops, and Exchange servers - usable in different combinations to support different ways the firewalls can detect which network traffic is linked to which users and mobile devices.

SSL VPN Client - a VPN client for laptop and desktop users connecting to the SSL VPN service on Watchguard firewalls.

111 questions
22
votes
4 answers

Is there a real way to connect to WatchGuard's VPN from Linux?

WatchGuard officially has clients only for Windows and Mac. But I see that it uses openvpn internally. I couldn't connect to WG from Linux. Is there someone who actually get this working? How?
Sergey Kirienko
6
votes
5 answers

Adding second firewall to ISP connection with multiple subnets?

My routing knowledge is a little rusty. I have a fibre internet connection hooked up like this: The managed switch breaks out VLANS for transparent lan service that is also through the ISP's box. I think that's mostly irrelevant for this problem,…
Grant
  • 17,671
  • 14
  • 69
  • 101
5
votes
3 answers

Watchguard mobile vpn: failed to get domain name

I am struggling to connect to a VPN using Watchguard's Mobile VPN client, and could use some help. The error I'm getting is the following one (even with log level = debug), which I can't manage to find helpful: 2016-06-13T14:21:10.337 Launching…
J. Mac
  • 51
  • 1
  • 1
  • 2
4
votes
2 answers

Two companies one Internet connection, Passthrough Public IP

My client is the tenant who will be sharing Internet from the other tenant. The other tenant has a WatchGuard in place. I am not familiar with WatchGuard or their interface. The IT guy I am working with is struggling with the setup so I am trying…
4
votes
2 answers

Watchguard L2TP over IPsec passthrough

I'm attempting to connect to a VPN (L2TP over IPsec) server through (not to) a WatchGuard XTM 505 appliance. I have the VPN server setup behind the firewall on a 1-to-1 NAT, and other protocols (such as HTTP traffic) are forwarded to that server…
Chris Tonkinson
  • 465
  • 2
  • 6
  • 18
4
votes
2 answers

tcp syn checking

I have a WatchGuard Firebox that I've recently configured. All of the policies look fine and all appropriate services seem to be working correctly. However, one or two (seemingly) random nodes keep getting blocked from making HTTP requests to a 1:1…
Chris Tonkinson
  • 465
  • 2
  • 6
  • 18
3
votes
0 answers

How to block AnonymoX addon operations with Watchguard XTM

We are using Watchguard XTM 502 as firewall in our office. Some of our employee using AnonymoX addon proxy on firefox. Normally Watchguard XTM block proxy. But Watchguard XTM 502 can't able to block AnonymoX. Here how can i block AnonymoX addon…
Kumar
  • 43
  • 1
  • 5
3
votes
1 answer

How do I configure port forwarding on a Watchguard XTM 2?

I have one external static IP that is nat'ed by the XTM to a local network, I would to be able to configure port forwarding on it (say external:80 -> 10.0.1.43:80 and external:2340 -> 10.0.1.48:2340). How can I do this on the Watchguard XTM 2?
vfilby
  • 177
  • 2
  • 3
  • 9
2
votes
1 answer

Loading website on port 1433 without using ":1433"

Boss wants me to set up a website so that by typing "https://www.example.com" (no :1433) in the address bar of a web browser, the request will go through port 1433 on a Watchguard Firebox to an apache web server with domain-ssl.conf…
NeghVar
  • 21
  • 1
2
votes
1 answer

VPN from WatchGuard to Google Cloud Platform: "establishing IKE_SA failed, peer not responding"

We are trying to "Build a VPN from a Watchguard to Google Cloud Platform" just like what is described here: https://querblick-it.de/build-vpn-watchguard-google-cloud-platform/ And under Remote peer IP address in Interconnect/VPN section of the the…
2
votes
2 answers

WatchGuard Port Forwarding / Static NAT

I'm trying to forward a specific port on my WatchGuard firewall to an internal host in a specific VLAN. My setup is roughly as follows: INTERNET vv WatchGuard vv--------vv--------vv [VLAN1] [VLAN2] [VLAN3] vv …
Lars
  • 484
  • 5
  • 19
2
votes
2 answers

Firewall Authentication - logon failed

I am attempting to use a Watchguard firebox 550e with Fireware XTM 11 to authenticate incoming traffic for RDP access. I have configured the firewall to use my domain controller for Active directory authentication with a Windows 2000 server farm…
RoseofPurple
  • 106
  • 2
  • 5
2
votes
2 answers

Watchguard firebox: public IP addresses behind firewall with as much usable IP addresses as possible

Our ISP assigned us 16 public IP addresses that we want to assign to hosts behind a Watchguard firebox x750e. The IP addresses are: x.x.x.176/28 of which x.x.x.177 is the gateway. The hosts will be running software that needs to be directly assigned…
lbarbosa
  • 123
  • 1
  • 5
2
votes
1 answer

Watchguard Firewall - Issues with SSLVPN

I have a client who has a WatchGuard XTM 23 device on site as their primary firewall. I just upgraded its firmware a couple days ago to the latest version for that series, 11.6.6. The problem is that I haven't successfully been able to setup a VPN…
David W
  • 3,405
  • 5
  • 34
  • 61
2
votes
3 answers

IP Address Conflict with Router/Firewall

I've been having IP issues with my local box for a couple months now. Usually when it starts acting up I don't have the patience to look into it, so I just drop onto DHCP, but this morning I've finally decided to figure out what's going on. I'm on…
jwegner
  • 493
  • 5
  • 10
1
2 3 4 5 6 7 8